Description Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php. Remediation References CVE-2022-26266 Related Vulnerabilities WordPress Plugin Backup Migration Arbitrary File Download (1.3.6) MySQL CVE-2012-1688 Vulnerability (CVE-2012-1688) WordPress Plugin Music Store Cross-Site Scripting (1.0.41) ZenCart Improper Authentication Vulnerability (CVE-2009-2255) WordPress Plugin SoundPress Cross-Site Scripting (2.2.6) Severity High Classification CVE-2022-26266 CWE-138 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities